UNC2682
UNC2682 is a Mandiant-tracked intrusion activity cluster associated with post-exploitation activity on SonicWall Email Security (ES). In the described intrusion, the actor deployed a web shell on a SonicWall ES server, gaining command execution with inherited NT AUTHORITY\SYSTEM privileges, and attempted to reduce visibility by clearing the SonicWall webUI log file. Mandiant states it prevented UNC2682 from completing its mission, and the actor’s ultimate objectives remain unknown. Observed tradecraft included heavy use of living-off-the-land techniques for credential access and post-exploitation. UNC2682 exported the HKLM\SAM, HKLM\SYSTEM, and HKLM\SECURITY registry hives, and used rundll32.exe with comsvcs.dll MiniDump to dump memory from lsass.exe and the Apache Tomcat process. The actor staged data by using an existing 7-Zip installation to compress a subdirectory of \data\archive, which contains daily archives of emails processed by SonicWall ES. After a pause consistent with offline password recovery attempts, UNC2682 moved laterally because the victim reused the same local Administrator password across multiple domain hosts. For lateral movement and remote execution, the actor used Impacket WMIEXEC.py over DCOM/WMI, followed by brief internal reconnaissance before containment and removal. No additional aliases, sub-groups, or nation-state attribution are provided in the content beyond the Mandiant tracking name UNC2682.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.